const res = await fetch('https://sandbox.trdrs.co/api/connect/links', {
method: 'POST',
headers: {
'content-type': 'application/json',
Authorization: `Bearer ${process.env.TRDRS_API_KEY}`,
"Idempotency-Key": "example-request-1",
},
body: JSON.stringify({
"origin": "https://app.example.com",
"trader": "trader-8841",
"expiresInSeconds": 300
}),
})
const data = await res.json()curl -X POST 'https://sandbox.trdrs.co/api/connect/links' \
-H "Authorization: Bearer $TRDRS_API_KEY" \
-H 'Idempotency-Key: example-request-1' \
-H 'content-type: application/json' \
-d '{"origin":"https://app.example.com","trader":"trader-8841","expiresInSeconds":300}'import requests
url = "https://sandbox.trdrs.co/api/connect/links"
payload = {
"origin": "https://app.example.com",
"trader": "trader-8841",
"expiresInSeconds": 300
}
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://sandbox.trdrs.co/api/connect/links",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'origin' => 'https://app.example.com',
'trader' => 'trader-8841',
'expiresInSeconds' => 300
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"Idempotency-Key: <idempotency-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://sandbox.trdrs.co/api/connect/links"
payload := strings.NewReader("{\n \"origin\": \"https://app.example.com\",\n \"trader\": \"trader-8841\",\n \"expiresInSeconds\": 300\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://sandbox.trdrs.co/api/connect/links")
.header("Idempotency-Key", "<idempotency-key>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"origin\": \"https://app.example.com\",\n \"trader\": \"trader-8841\",\n \"expiresInSeconds\": 300\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://sandbox.trdrs.co/api/connect/links")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Idempotency-Key"] = '<idempotency-key>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"origin\": \"https://app.example.com\",\n \"trader\": \"trader-8841\",\n \"expiresInSeconds\": 300\n}"
response = http.request(request)
puts response.read_body{
"link": {
"id": "00000000-0000-0000-0000-000000000001",
"token": "trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA",
"expiresAt": "2026-09-14T12:00:00.000Z",
"origin": "https://app.example.com",
"environment": "sandbox"
}
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}Create a Connect link
Creates a Connect link for one of your traders, so they can connect an account, or open your white-label paper, in hosted Connect on your website without signing in to trdrs. Name the trader by your own id for them: the first link for an id makes them one of your traders at trdrs, every later link reaches the same trader, and the accounts they connect are theirs, apart from any trdrs account and from every other app’s traders. The response’s link carries its token, which you hand to your page, and its id, which you keep to read how it ended. The token opens hosted Connect on that one website until expiresAt, and once open, Connect stays usable for up to 30 minutes. The same Idempotency-Key and body answer the same link until it is opened, so send a new key for each new link. Your API key stays on your server. It takes your app’s API key, sent from your server: a request that also carries a cookie or a browser’s Origin is refused. Preview: served on the sandbox, where it is free.
const res = await fetch('https://sandbox.trdrs.co/api/connect/links', {
method: 'POST',
headers: {
'content-type': 'application/json',
Authorization: `Bearer ${process.env.TRDRS_API_KEY}`,
"Idempotency-Key": "example-request-1",
},
body: JSON.stringify({
"origin": "https://app.example.com",
"trader": "trader-8841",
"expiresInSeconds": 300
}),
})
const data = await res.json()curl -X POST 'https://sandbox.trdrs.co/api/connect/links' \
-H "Authorization: Bearer $TRDRS_API_KEY" \
-H 'Idempotency-Key: example-request-1' \
-H 'content-type: application/json' \
-d '{"origin":"https://app.example.com","trader":"trader-8841","expiresInSeconds":300}'import requests
url = "https://sandbox.trdrs.co/api/connect/links"
payload = {
"origin": "https://app.example.com",
"trader": "trader-8841",
"expiresInSeconds": 300
}
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://sandbox.trdrs.co/api/connect/links",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'origin' => 'https://app.example.com',
'trader' => 'trader-8841',
'expiresInSeconds' => 300
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"Idempotency-Key: <idempotency-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://sandbox.trdrs.co/api/connect/links"
payload := strings.NewReader("{\n \"origin\": \"https://app.example.com\",\n \"trader\": \"trader-8841\",\n \"expiresInSeconds\": 300\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://sandbox.trdrs.co/api/connect/links")
.header("Idempotency-Key", "<idempotency-key>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"origin\": \"https://app.example.com\",\n \"trader\": \"trader-8841\",\n \"expiresInSeconds\": 300\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://sandbox.trdrs.co/api/connect/links")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Idempotency-Key"] = '<idempotency-key>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"origin\": \"https://app.example.com\",\n \"trader\": \"trader-8841\",\n \"expiresInSeconds\": 300\n}"
response = http.request(request)
puts response.read_body{
"link": {
"id": "00000000-0000-0000-0000-000000000001",
"token": "trdrs_cl_sandbox_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA",
"expiresAt": "2026-09-14T12:00:00.000Z",
"origin": "https://app.example.com",
"environment": "sandbox"
}
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}{
"error": "invalid_instrument"
}Authorizations
A Connect app's API key (trdrs_ck_sandbox_… or trdrs_ck_production_…), in preview. It belongs to one app in one environment, has a name and an expiry, and carries the whole Connect API. An owner of the app creates it in the Connect dashboard. It creates, reads and closes the app's Connect links under /api/connect/links, and on the account, market and trading routes it reads the app's own traders' accounts and market data and routes their orders, each request naming its trader in x-trdrs-trader. It stops working when it is revoked or expires, or when the owner who created it stops being an owner. Keep it on your server.
Headers
A key you choose, 1 to 128 characters, that identifies this write. Send the same key when you retry it, so the write is never applied twice.
1 - 128Body
The website of the page that opens hosted Connect, exactly as you added it.
Your own id for the trader, the same every time they connect: letters, digits, dot, underscore, colon and hyphen, up to 128 characters, starting with a letter or a digit. Never an email or another personal detail.
^[A-Za-z0-9][A-Za-z0-9._:-]{0,127}$How long the token can open hosted Connect, from 60 to 600 seconds.
60 <= x <= 600Response
Success. The response is sent with Cache-Control: no-store, so don't cache it.
Show child attributes
Show child attributes